Crispin la valiente/Getty Images
Iâm all about new technology, but sometimes, new technology gets in its own way, and passkeys epitomize this more than any other technology.
For those who do not know, passkeys are the new password, only more secure.
Also: How passkeys work: The complete guide to your inevitable passwordless future
Essentially, a passkey is a digital credential that allows you to log into your accounts using biometric (fingerprints or facial scans) and/or non-biometric (PINs, patterns, or device passwords) authentication â instead of having to type (and remember) a password. Passkeys use public key cryptography to enhance authentication, making them far more resistant to phishing and other types of attacks.Â
Anyone interested in a fuller exploration of passkeys is encouraged to check out David Berlindâs deep-dive series, How passkeys work.
Passkeys are real, and they are coming for your passwords.
On paper, passkeys are great. They make logins more secure and easier.Â
On paper.
In reality⌠not so much.
Let me paint a picture.
Recently, I was setting up an Android tablet to review. When it came to linking the tablet to my Google account, I was expecting it to go the usual route and ask me to âSay Yes on my phone,â but that didnât happen. Instead, it wanted to use my passkey. I tapped âUse your passkey,â only to see that it couldnât find my passkey.
Also:Â If we want a passwordless future, letâs get our passkey story straight
Wait, Iâve created a passkey for my Google account.Â
I tried again.Â
Nothing.
I decided to tap âTry another way,â but the only option was still a passkey.Â
If the tablet couldnât find the passkey Iâd created and wouldnât allow me to use another method of logging into my account, what was I to do?
Fortunately, I continued attempting the passkey option, and eventually it allowed me to tap âSay Yes on your phone.â Whew. I was finally able to log in.
Also:Â Why the road from passwords to passkeys is long, bumpy, and worth it â probably
After that crazy roundabout, I hopped onto the Google Passkey manager to check into my passkey. While attempting to log in, at the 2-Step Verification phase, the only option was, again, âUse your passkey.â I clicked it, only to find out the passkey was assigned to my old Pixel 8 Pro (which I no longer had).
Thankfully, after clicking âUse a different phone,â Google presented me with a QR code to scan. I scanned the code, only to then be presented with a pop-up informing me that something went wrong. It didnât say what, it just said âsomething.âÂ
I tried again. This time I clicked âCreate a passkey,â only to be told that a passkey couldnât be created on this device because it doesnât support passkeys. Is that because my desktop PC doesnât have biometrics?
What gives? Why is this so hard?
I write about technology, and Iâve been using technology for a long time. I know technology, so this should be second nature to me. I can use SSH key authentication and PGP encryption, so passkeys should be a no-brainer for me.
The solution was to use the Google Passkey manager on my phone and create a passkey.
Also: What really happens during your âpasswordlessâ passkey login?
Only Google informed me that I already had a passkey on my device. If thatâs the case, why didnât it work when I attempted to log into my Google account on the tablet? When I was logging into the tablet, Google should have been aware I had a passkey on my Pixel 9 Pro and requested I authenticate with either a fingerprint or face scan. It didnât. No passkey was recognized⌠even though itâs there.
Itâs a recursive nightmare from which I canât seem to escape.
Now, letâs consider a user who knows little or nothing about technology â think about how frustrating it would be to try creating and using a passkey. How would your grandmother deal with this? Sheâd be calling you on the phone â the very device on which sheâs trying to create a passkey â frustrated and concerned.Â
You donât want Meemaw concerned, right?
Also:Â 7 password rules security experts live by â the last one might surprise you
Simply put, passkeys are not ready for the average user. Until Google (and every other company employing this technology) can figure out a seamless way of creating and using passkeys, they should consider them in beta.
I get it, I really do. Usernames and passwords are obsolete. Theyâre simple to crack because they allow users to be lazy with their credentials. But until passkeys can be easily created and used, this so-called passwordless alternative will accomplish nothing but infuriate people.
I want passkeys to work. I like the idea behind them and believe they are the authentication method of the future. But for the love of DwvvfPt05qDzQrZGdW5wr! To every company that wants to make passkeys its default login method:
Also:Â The best security keys of 2025: Expert tested
Before you migrate from passwords, make sure the technology is easy enough for anyone to use. When you make things harder, users want to throw their phones off the highest mountain.
Thatâs not good for the company, and itâs not good for Meemaw.
Stay ahead of security news with Tech Today, delivered to your inbox every morning.

